Meta patches Muse flaw that exposed its AI assistant to local code
A macOS vulnerability could let local apps redirect Muse’s cloud transcription and expose an account token, according to security researcher Patrick Wardle.

Meta said it released a hotfix for a zero-day vulnerability in Muse, its macOS AI assistant. Security researcher Patrick Wardle found that local apps or terminal commands could change undocumented settings, including the server endpoint used for cloud transcription.
Wardle told WIRED that redirecting transcription to an attacker-controlled server could expose the token used to access a Muse account. He developed proof-of-concept attacks showing how Muse’s own privileges could be misused, including to write files to disk and take pictures.
Muse can connect to users’ accounts and access Mac resources to handle tasks such as purchases, documents and appointments. That breadth of access makes the flaw consequential: compromising the assistant could give an attacker access to capabilities users had granted it.
The supplied reporting does not establish that the vulnerability was exploited against real users. Meta described the flaw as not being a remote exploit, while Wardle demonstrated a scenario involving a terminal command and said social engineering could help trigger an attack.
Amazon’s decision to block Muse from shopping on its site was separate from the security issue. The company cited its Conditions of Use for unauthorised AI agents and said it had asked Meta to remove Amazon from Muse’s experience.
Wardle plans to discuss the vulnerability and broader AI assistant threats at a security conference in November. Meta has not explained why Muse uses cloud transcription rather than the on-device transcription option available in macOS.

